Light

Episode #850 Quiz

It's a Log4j Christmas
Date: 2021-12-21 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome patched its 16th 2021 zero-day, a V8 use-after-free. Firefox briefly broke Microsoft.com because OCSP Must Staple plus SHA-256 stapled responses were mishandled, then fixed it. Mozilla blocked Windows Cloud Clipboard syncing of Firefox passwords. Researchers showed spoofed cellular handover reports and WiFi-Bluetooth coexistence attacks enabling interception, credential theft, and code execution.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific change did Firefox 95.0.1 make to restore access to Microsoft domains after the OCSP issue described in the episode?
Question 2: Why did Mozilla block Firefox passwords copied from about:logins from being placed into Windows Cloud Clipboard history?
Question 3: What was the key weakness in the cellular handover procedure that the researchers abused to strengthen Stingray-style attacks?
Question 4: According to the episode, what did the Bluetooth/WiFi coexistence research show was possible on affected chips?
Question 5: What did Google’s scan of Maven Central conclude about the scale of Log4Shell exposure in the Java ecosystem?
Cancel